Open-source software vs. the proposed Cyber Resilience Act (NLnet Labs)
Open-source software vs. the proposed Cyber Resilience Act (NLnet Labs)
Posted Nov 15, 2022 15:49 UTC (Tue) by jpfrancois (subscriber, #65948)In reply to: Open-source software vs. the proposed Cyber Resilience Act (NLnet Labs) by eduperez
Parent article: Open-source software vs. the proposed Cyber Resilience Act (NLnet Labs)
I honestly don't know how you qualify a "security hole" for a "custom distro" If a library with a CVE is used, but is never exposed to malicious input, how is that a problem for the shipped hardware ? And I am pretty sure this kind of custom distro (buildroot / openembedded) is heavily used.
Rules for hardware conformance don't change every now and then. Yet hardware certification is a time consuming process with bureaucratic traps.
CVE list on the other hand, change every day.
This can raise the bar and improve the global software security status. But I know our barely profitable (but growing) business would be much less profitable if we had to have someone to do this kind of security analysis in house.
